📦

php-nuke

Vendor: francisco_burzi

Actively Exploited 0 CISA KEV List
PoC / Exploits 65 Code Available
Total RCEs 3 Remote Access
Total CVEs 195 Total Indexed
Avg. EPSS 3.44% Exploit Prob.
Latest CVE CVE-2021-30177 Apr 07

Security Vulnerability Index

Page 11 / 20
4.3 CVSS
CVE-2003-1400
Exploit Found

Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar parameter.

EPSS: 1.45%
7.5 CVSS
CVE-2003-1210
Exploit Found

Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function.

EPSS: 5.36%
4.3 CVSS
CVE-2003-1468
Exploit Found

The Web_Links module in PHP-Nuke 6.0 through 6.5 final allows remote attackers to obtain the full web server path via an invalid cid parameter that is non-numeric or null, which leaks the pathname in an error message.

EPSS: 2.27%
6.5 CVSS

Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 5.6 and 6.5 allow remote authenticated users to execute arbitrary SQL commands via (1) a uid (user) cookie to modules.php; and allow remote attackers to execute arbitrary SQL commands via an aid (admin) cookie to the Web_Links module in a (2) viewlink, (3) MostPopular, or (4) NewLinksDate action, different vectors than CVE-2003-0279.

EPSS: 0.95%
4.3 CVSS

Cross-site scripting (XSS) vulnerability in block-Forums.php in the Splatt Forum module for PHP-Nuke 6.x allows remote attackers to inject arbitrary web script or HTML via the subject parameter.

EPSS: 1.22%
5.0 CVSS

PHP-Nuke 7.0 allows remote attackers to obtain the installation path via certain characters such as (1) ", (2) ', or (3) > in the search field, which reveals the path in an error message.

EPSS: 0.97%
7.5 CVSS
CVE-2003-1435
Exploit Found

SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.

EPSS: 1.73%
2.6 CVSS

Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php.

EPSS: 1.18%
4.3 CVSS

Cross-site scripting (XSS) vulnerability in the Statistics module for PHP-Nuke 6.0 and earlier allows remote attackers to insert arbitrary web script via the year parameter.

EPSS: 1.04%
5.0 CVSS
CVE-2002-2032
Exploit Found

sql_layer.php in PHP-Nuke 5.4 and earlier does not restrict access to debugging features, which allows remote attackers to gain SQL query information by setting the sql_debug parameter to (1) index.php and (2) modules.php.

EPSS: 5.85%